System and Method for Securing a Telephone System Comprising Circuit Switched and IP Data Networks
Abstract
The present invention discloses a system and method for securing a telephone system comprising a circuit switched network and an IP data network. The system comprises a first firewall, between an internal IP data network and an external IP data network, for protecting the internal IP data network against intrusion; a second firewall, between the internal IP data network and a circuit switched network, for preventing intrusion originated in the external IP data network into the circuit switched network; a third firewall for protecting voice-over-IP phones against intrusion from the external IP data network; intrusion detection system (IDS) probes and time-division multiplexing (TDM) voice probes for extracting information about voice-over-IP calls over the internal IP data network; a Session Initiation Protocol (SIP) proxy server for managing voice-over-IP call control signals; and a security supervisor for managing the operation of the firewalls and the IDS and TDM voice probes.
Claims
exact text as granted — not AI-modified1 . A system for securing a telephone system comprising at least one circuit switched network and at least one IP data network, the system comprising:
a first firewall, situated between an internal IP data network and an external IP data network, for protecting the internal IP data network against intrusion; a second firewall, situated between the internal IP data network and a circuit switched network, for preventing intrusion that is originated in the external IP data network into the circuit switched network; a third firewall for protecting a plurality of voice-over-IP phones against intrusion from the external IP data network; at least one intrusion detection system (IDS) probe and at least one time-division multiplexing (TDM) voice probe for extracting information about voice-over-IP calls over the internal IP data network; a Session Initiation Protocol (SIP) proxy server for managing voice-over-IP call control signals; and a security supervisor for managing the operation of the first, the second and the third firewalls and the at least one IDS probe and the at least one TDM voice probe.
2 . The system of claim 1 , wherein the first firewall manages one or more communication ports to control exchange of voice data between the internal IP data network and the external IP data network.
3 . The system of claim 1 , wherein the second firewall manages communication ports to control exchange of voice data between the internal IP data network and the circuit switched network.
4 . The system of claim 1 , wherein the third firewall manages communication ports to control voice data to and from the plurality of voice-over-IP phones.
5 . The system of claim 1 , wherein the at least one IDS probe extracts information from SIP call control signals.
6 . The system of claim 1 , wherein the at least one TDM voice probe synchronizes with the security supervisor to determine whether to deny a call control request from a caller by blocking it from a firewall.
7 . The system of claim 1 , wherein the SIP proxy server comprises a registration server and an authentication server.
8 . The system of claim 7 , wherein the SIP proxy server further comprises a detective module.
9 . The system of claim 8 , wherein the detective module extracts caller and callee information from the call control signals.
10 . The system of claim 8 , wherein the detective module is pre-configured with a set of static rules for detecting predetermined malicious attacks.
11 . The system of claim 7 , wherein the registration server records a predetermined association between the user/phone number and the address of a SIP phone.
12 . The system of claim 7 , wherein the authentication server authenticates the caller's identity.
13 . The system of claim 1 , wherein the security supervisor comprises an audit supervisor, an expert system, a database, and at least one security module.
14 . The system of claim 13 , wherein the audit supervisor analyzes the capabilities of the SIP proxy server and the plurality of SIP phones.
15 . The system of claim 1 , wherein the security supervisor receives caller and callee information that is extracted from voice data by the IDS probes, the TDM voice probe, and the SIP proxy server.
16 . A method for securing a telephone system with at least one circuit switched network and at least one IP data network by using one or more firewalls to protect voice-over-IP calls, the method comprising:
dividing the telephone system into a plurality of security zones and assigning a security level to one or more communication devices in the plurality of security zones; verifying that a caller initiating at least one call control signal and a SIP proxy server are originated from at least one trusted domain and that the caller is allowed to establish a voice-over-IP call with a callee in the telephone system based on a security rule; confirming a caller's authenticity with the SIP proxy server via a secured channel that is established by using the one or more Secure Sockets Layer certificates; opening at least one communication port on the one or more firewalls for the voice-over-IP call; and monitoring the at least one call control signal and the voice-over-IP call to gather information about the voice-over-IP call.
17 . The method of claim 16 , wherein the dividing the telephone system into the plurality of security zones depends on a location and importance of the user of the communication device.
18 . The method of claim 16 , wherein the confirming the caller's authenticity is carried out using a proprietary dialog between the SIP proxy servers of the caller and callee.
19 . The method of claim 16 , wherein the communication ports must not be numbered sequentially.
20 . The method of claim 16 , wherein the monitoring the at least one call control signal and the voice-over-IP call further comprises:
examining the at least one call control signal to detect spoofing of the information; monitoring the content of voice data to detect overloading of the at least one IP data network by attackers; preventing a communication device from being stalked by attackers; and protecting a plurality of servers in a telephone system against denial-of-service attacks.
21 . The method of claim 20 , wherein the examining the at least one call control signal further comprises:
verifying that a caller is authorized to re-direct a call to another communication device or another area; verifying that an incoming call is originated from the caller in a confirmed security zone; verifying that the at least one call control signal traverses a coherent path; and verifying that a modification of the properties of an on-going voice-over-IP call is authorized.
22 . The method of claim 20 , wherein the monitoring the content of voice data includes analyzing and comparing a temporal property of a voice data flow with a pattern associated with the voice codec.
23 . The method of claim 20 , wherein the preventing the communication device from being stalked by attackers depends on collecting statistics including the number of calls within a predetermined period, the average time interval between two consecutive calls, and the identity of the caller.
24 . The method of claim 20 , wherein the protecting the plurality of servers in the telephone system against denial-of-service attacks further comprises:
monitoring volume and pattern of on-going calls that enter the telephone system; and limiting the number of requests that enter the telephone system within a predetermined period of time system and method for securing a telephone system comprising circuit switched and IP data networks.Join the waitlist — get patent alerts
Track US2008089494A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.